List your product on Stack Search

Get in front of thousands of GRC decision-makers

IT Security & Privacy

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Case

TikTok and its parent company ByteDance have agreed to pay $400 million to settle a U.S. government lawsuit alleging the platform collected personal information from millions of children without their parents' consent, according to BBC reporting, closing a case that began two years ago and adding another substantial figure to the growing cost of getting children's privacy wrong.

Ofcom Sets Out Enforcement Approach as UK Online Safety Regime Takes Hold

Ofcom has set out how it plans to enforce the UK’s Online Safety Act across more than 100,000 companies, detailing an approach that can begin with guidance and direct regulatory pressure but escalate to investigations, fines and, in certain cases, measures that disrupt a company’s business.

Cyberattack Exposes Data of 8.7 Million Customers at Three Major UK Airports

Manchester Airports Group said criminal hackers accessed data belonging to about 8.7 million customers in a cyberattack affecting systems used across Manchester, London Stansted and East Midlands airports, one of the largest breaches of customer information disclosed by a UK airport operator.

CISA Red Team Tests Expose a Divide in How Security Teams Respond to Intrusions

At one critical infrastructure organization, CISA’s red team got in and kept going. It compromised multiple workstations, elevated its privileges over the domain and began moving laterally into other systems and resources. The security operations center never detected it.

Uber Faces €825 Million Fine Over Automated Driver Deactivations in French-Dutch GDPR Case

Uber’s software could cut a driver off from the platform for suspected fraud or poor customer ratings. What it did not necessarily do first was ask a person. That has now cost the company €824.99 million.

South Korea Rethinks Privacy Rules as AI Strains the Logic of Consent

The Personal Information Protection Commission has opened a public consultation on an overhaul of the country’s privacy protection framework, a review prompted in part by the widening distance between rules built around consent and forms of data processing that have become considerably harder to explain, much less reduce to a series of yes-or-no decisions.

Pokémon Center Customer Data Exposed in CEVA Logistics Cyberattack

Pokémon Center is notifying customers in the United Kingdom and Germany that personal and order information may have been exposed in a cyberattack on CEVA Logistics, the third-party provider it uses to fulfill and ship orders in those markets.